New from Jen Easterly and me: as threats to our critical infrastructure increase, U.S. policymakers need to defend + strengthen the role of security research. This is personal for me, having received legal threats for good-faith security research.
We call on Congress to protect security researchers by codifying the DMCA security research exemption, exempt good-faith security research from the CFAA, and require software vendors to operate a VDP and publish CVEs.
https://www.lawfaremedia.org/article/advancing-secure-by-design-through-security-research